Artificial intelligence company Hugging Face disclosed that secrets from its Spaces platform may have been accessed without proper authorization last week.The Hugging Face Spaces platform enables users and organizations to host interactive demos of its machine learning (ML) applications.Hugging Face said in a post Friday that it detected the potential intrusion earlier last week, leading the company to discover that a “subset of Spaces’ secrets” may have been exposed to an unauthorized party.The secrets leaked included Hugging Face tokens, which the company revoked after discovering the suspicious activity; affected users received an email prior to the Friday disclosure, according to the company. The disclosure notice also noted several security changes made to the Spaces platform in response to the leak, including the removal of org tokens to improve traceability and auditing capabilities, and the implementation of a key management service (KMS) for Spaces secrets.Hugging Face said it plans to deprecate traditional read and write tokens “in the near future,” replacing them with fine-grained access tokens, which are currently the default.Spaces users are recommended to switch their Hugging Face tokens to fine-grained access tokens if they are not already using them, and refresh any key or token that may have been exposed.The company brought in third-party cybersecurity forensic experts to help investigate the incident and help review security practices; the incident was also reported to law enforcement and data protection authorities.Further details about the suspected unauthorized access were not provided, and Hugging Face did not immediately respond to inquiries from SC Media regarding the number of affected users and origin of the intrusion.
AI/ML, AI benefits/risks, Vulnerability Management
AI firm Hugging Face discloses leak of secrets on its Spaces platform

(Credit: Tada Images, Adobe Stock)
An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds